Every day, security researchers and threat actors probe public-facing systems, including government services. Someone will eventually find a weak spot. What matters is who finds it first.
The Government of Canada’s new Coordinated Vulnerability Disclosure (GC CVD) program gives external security researchers a standardized, GC-wide channel to responsibly report vulnerabilities to participating GC services.
The GC CVD program provides clear rules of engagement, a legal safe harbour for good-faith research, and centralized intake through the HackerOne platform, managed by the Treasury Board of Canada Secretariat (TBS). This gets issues to the right teams.
TBS validated the program through a pilot with a small group of early adopters. As one of the first participants, the Canadian Digital Service (CDS) helped test the workflow and provided feedback to shape the GC-wide program.
Our Security team shares what they learned.
Addressing a critical challenge
Historically, researchers lacked a clear way to report vulnerabilities, while organizations received reports through informal channels that were difficult to validate or action.
Responsible vulnerability disclosure is essential in modern cyber security. Giving ethical researchers a safe, structured reporting channel helps organizations identify, triage, and remediate issues with proper oversight before attackers exploit them.
Joining the CVD pilot
CDS chose to join the pilot early for three main reasons:
- Catching issues earlier:
Giving ethical researchers a safe channel increases the chances we’ll learn about serious vulnerabilities before attackers. - Helping shape the GC’s approach:
As an early adopter, CDS could provide practical feedback to TBS on how the program runs day‑to‑day. - Providing a concrete example for other departments:
By going first, CDS could show that CVD fits into normal security operations.
From the TBS perspective, CDS’s participation served as an important proof point for the program:
“Working with CDS on this pilot gave us our first full, end‑to‑end test of the Government of Canada’s CVD process outside a planning document. Overall, the pilot surfaced high‑impact issues that traditional tools hadn’t caught yet, including vulnerabilities with tens of thousands of dollars in estimated mitigated losses. Having a concrete case like CDS gives future departments something real to point to when they consider joining the program.”
– Po Tea-Duncan, GC Chief Information Security Officer (CISO), TBS
How the pilot came together
Our Security team worked closely with our product teams, Site Reliability Engineering (SRE), and TBS to:
- Identify which public-facing assets would take part.
- Deploy RFC 9116-compliant security.txt files across participating domains (standard files that tell researchers how to report an issue).
- Validate incoming reports and coordinate fixes.
- Improve our internal roles and responsibilities.
- Prepare guidance for engineering teams.
TBS managed the HackerOne platform, researcher communications, and initial triage, while CDS validated findings, weighed business context, prioritized remediation, and implemented fixes. This let engineering teams focus on security improvements while TBS maintained GC-oversight.
Learning through the process
The morning after the pilot opened to public researchers, before any formal announcement, several product teams opened security incidents after noticing unexpected activity against public-facing services. For a short time, we did not know whether it was malicious or related to the pilot.
It soon became clear: ethical researchers had begun testing systems newly added to the pilot. The experience tested CDS’s incident response and coordination across Security, SRE, and product teams. Within hours, we had:
- Confirmed that activity was within the pilot’s rules of engagement,
- Validated that our monitoring and alerting were working as intended, and
- Exercised our internal playbooks under realistic conditions.
That morning highlighted our team’s readiness for future reports and gave TBS valuable insight into the GC CVD workflow functions under real operating conditions.
Results and key takeaways
The pilot confirmed that CVD is fundamentally a governance capability: processes, roles, and decision-making matter more than support tools such as HackerOne.
CDS’s key outcomes included:
- A repeatable internal process:
We now have a clear, repeatable process for receiving and managing external vulnerability reports, from intake to remediation and closure. - Improved cross-team coordination:
The pilot strengthened collaboration between security, engineering, operations, and product teams ahead of broader GC CVD adoption. - Stronger overall security posture:
CVD reports fed into our existing vulnerability management and incident response processes, improving operational readiness and making our services more resilient. - Evidence that GC CVD surfaces real, high-impact issues:
Researchers found a range of vulnerabilities that might otherwise have been missed or found later at greater cost. - Practical feedback into the GC-wide program:
Our experience helped TBS refine policy language, onboarding materials, and operational guardrails for future participants.
The pilot exceeded our expectations. It strengthened cross-team collaboration, increased confidence in our response processes, and showed that coordinated vulnerability disclosure can run as part of day-to-day operations with minimal disruption.
Building a more secure future
We now have a stronger process for handling vulnerability reports and working with the research community. This aligns with our security principles: catch issues early, report them responsibly, and triage and fix them effectively.
Predictable governance strengthens the security of the digital services Canada depends on.
CDS plans to build on these lessons by maturing vulnerability management, refining internal guidance, preparing for future reports, and supporting GC-wide adoption.
For other GC organizations, CDS shows that GC CVD can integrate with existing security operations, reveal high-impact vulnerabilities, and be implemented in partnership with TBS.
Responsible vulnerability disclosure is now a permanent part of our security landscape. By working with TBS and the research community, we’re helping to strengthen people’s security.